CVE-2026-14794 | Craft CMS up to 4.18.0.1 Charts Endpoint ChartsController.php actionGetNewUsersData userGroupId improper authorization
A vulnerability marked as problematic has been reported in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization.
This vulnerability is tracked as CVE-2026-14794. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More